5091 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-51503
Software Genérico Web
7.6
HIGH
EPSS
0.2%
2025 1 PoC

A Stored Cross-Site Scripting (XSS) vulnerability in Microweber CMS 2.0 allows attackers to inject malicious scripts into user profile fields, leading to arbitrary JavaScript execution in admin browsers.

CVE-2025-24587
Email Subscription Popup Database
7.6
HIGH
EPSS
11.9%
2025 CWE-89 2 PoCs

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Nks Email Subscription Popup email-subscribe allows Blind SQL Injection.This issue affects Email Subscription Popup: from n/a through <= 1.2.23.

CVE-2025-9959
Software Genérico General
7.6
HIGH
EPSS
0.1%
2025 CWE-94 1 PoC

Incomplete validation of dunder attributes allows an attacker to escape from the Local Python execution environment sandbox, enforced by smolagents. The attack requires a Prompt Injection in order to trick the agent to create malicious code.

CVE-2025-29152
Software Genérico Web
7.6
HIGH
EPSS
0.3%
2025 2 PoCs

Cross-Site Scripting vulnerability in lemeconsultoria HCM galera.app v.4.58.0 allows an attacker to execute arbitrary code via multiple components, including Strategic Planning Perspective Registration, Training Request, Perspective Editing, Education Registration, Hierarchical Level Registration, Decision Level Registration, Perspective Registration, Company Group Registration, Company Registration, News Registration, Employee Editing, Goal Team Registration, Learning Resource Type Registration, Learning Resource Family Registration, Learning Resource Supplier Registration, and Cycle Maintena

CVE-2025-22710
Smart Manager Database
7.6
HIGH
EPSS
19.1%
2025 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in storeapps Smart Manager smart-manager-for-wp-e-commerce allows Blind SQL Injection.This issue affects Smart Manager: from n/a through <= 8.52.0.

CVE-2025-46349
yeswiki Web ⚡ nuclei
7.6
HIGH
EPSS
0.5%
2025 CWE-79 0 PoCs

YesWiki is a wiki system written in PHP. Prior to version 4.5.4, YesWiki is vulnerable to reflected XSS in the file upload form. This vulnerability allows any malicious unauthenticated user to create a link that can be clicked on by the victim to perform arbitrary actions. This issue has been patched in version 4.5.4.

CVE-2025-59251
Microsoft Edge (Chromium-based) General
7.6
HIGH
EPSS
0.1%
2025 CWE-121 1 PoC

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

CVE-2025-27461
Endress+Hauser MEAC300-FNADE4 Windows
7.6
HIGH
EPSS
0.3%
2025 CWE-862 1 PoC

During startup, the device automatically logs in the EPC2 Windows user without requesting a password.

CVE-2025-4123
Grafana DevOps Web ⚡ nuclei
7.6
HIGH
EPSS
5.3%
2025 CWE-79 10 PoCs

A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permissions and if anonymous access is enabled, the XSS will work. If the Grafana Image Renderer plugin is installed, it is possible to exploit the open redirect to achieve a full read SSRF. The default Content-Security-Policy (CSP) in Grafana will block the XSS though the `connect-src` directive.

CVE-2025-30921
Newsletters Database
7.6
HIGH
EPSS
0.4%
2025 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tribulant Software Newsletters newsletters-lite allows SQL Injection.This issue affects Newsletters: from n/a through <= 4.9.9.7.

CVE-2025-58789
WP Full Stripe Free Database
7.6
HIGH
EPSS
0.0%
2025 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle WP Full Stripe Free wp-full-stripe-free allows SQL Injection.This issue affects WP Full Stripe Free: from n/a through <= 8.2.5.

CVE-2025-2610
MagnusBilling Web ⚡ nuclei
7.6
HIGH
EPSS
1.6%
2025 CWE-79 1 PoC

Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling (Alarm Module modules) allows authenticated stored cross-site scripting. This vulnerability is associated with program files protected/components/MagnusLog.Php. This issue affects MagnusBilling: through 7.3.0.

CVE-2025-30072
Software Genérico General
7.6
HIGH
EPSS
0.2%
2025 2 PoCs

Tiiwee X1 Alarm System TWX1HAKV2 allows Authentication Bypass by Capture-replay, leading to physical Access to the protected facilities without triggering an alarm.

CVE-2025-22352
ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes Database
7.6
HIGH
EPSS
3.7%
2025 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ELEXtensions ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes elex-bulk-edit-products-prices-attributes-for-woocommerce-basic allows Blind SQL Injection.This issue affects ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes: from n/a through <= 1.4.9.

CVE-2025-45805
Software Genérico Web
7.6
HIGH
EPSS
0.0%
2025 1 PoC

In phpgurukul Doctor Appointment Management System 1.0, an authenticated doctor user can inject arbitrary JavaScript code into their profile name. This payload is subsequently rendered without proper sanitization, when a user visits the website and selects the doctor to book an appointment.

CVE-2025-27460
Endress+Hauser MEAC300-FNADE4 Windows
7.6
HIGH
EPSS
0.1%
2025 CWE-312 1 PoC

The hard drives of the device are not encrypted using a full volume encryption feature such as BitLocker. This allows an attacker with physical access to the device to use an alternative operating system to interact with the hard drives, completely circumventing the Windows login. The attacker can read from and write to all files on the hard drives.

CVE-2025-9072
Mattermost General
7.6
HIGH
EPSS
0.0%
2025 CWE-601 1 PoC

Mattermost versions 10.10.x <= 10.10.1, 10.5.x <= 10.5.9, 10.9.x <= 10.9.4 fail to validate the redirect_to parameter, allowing an attacker to craft a malicious link that, once a user authenticates with their SAML provider, could post the user’s cookies to an attacker-controlled URL.

CVE-2025-1933
Firefox General
7.6
HIGH
EPSS
0.5%
2025 1 PoC

On 64-bit CPUs, when the JIT compiles WASM i32 return values they can pick up bits from left over memory. This can potentially cause them to be treated as a different type. This vulnerability was fixed in Firefox 136, Firefox ESR 115.21, Firefox ESR 128.8, Thunderbird 136, and Thunderbird 128.8.

CVE-2025-25616
Software Genérico General
7.6
HIGH
EPSS
0.6%
2025 1 PoC

Unifiedtransform 2.0 is vulnerable to Incorrect Access Control, which allows students to modify rules for exams. The affected endpoint is /exams/edit-rule?exam_rule_id=1.

CVE-2025-12397
Looker Studio Database
7.6
HIGH
EPSS
0.0%
2025 CWE-89 1 PoC

A SQL injection vulnerability was found in Looker Studio. A Looker Studio user with report view access could inject malicious SQL that would execute with the report owner's permissions. The vulnerability affected to reports with BigQuery as the data source. This vulnerability was patched on 21 July 2025, and no customer action is needed.